Privacy Policy
What’s in this policy
- Who we are and what this covers
- Information we collect
- How we use information
- Legal bases for processing
- No sale of data and no ad tracking
- How we share information
- How long we keep information
- How we protect information
- Children’s privacy (COPPA)
- Your rights and choices
- California rights (CCPA / CPRA)
- Other United States state rights
- European and United Kingdom rights (GDPR)
- International data transfers
- Cookies and similar technologies
- Shopify integration (Helm Store Sync)
- Changes to this policy
- Contact us
1. Who we are and what this covers
This Privacy Policy explains how Helm Social, Inc. (“Helm,” “we,” or “us”), a United States company, collects, uses, and shares information when you use helmsocial.app, our mobile apps, live streaming, and related products and services (the “Service”). Helm is the controller of the personal information described here. By using the Service, you agree to this policy. If you do not agree, please do not use Helm.
2. Information we collect
2.1 Information you provide
- Account details. Email, password (stored only as a secure hash), display name, handle, date of birth or age, account type, and any profile information you add such as bio and avatar.
- Content you create. Posts, videos, photos, stash items, podcasts, long-form articles, comments, messages, live streams, reactions, follows, and related metadata.
- Family and consent records. If you link a Parent account to a child or teen, we record the relationship and the parent’s consent and approvals.
- Verification information. For Business, Brand, verified, or payout-eligible accounts, identity or entity details and documents you submit, and tax information.
- Support and communications. Messages you send us, reports you file, and survey responses.
2.2 Information we collect automatically
- Device and log data. IP address, browser and operating system, device identifiers, app version, referring pages, and timestamps, used to keep the Service secure and diagnose problems.
- Usage data. Screens you view, features you use, and aggregate engagement signals, used to operate and improve Helm, not to build advertising profiles.
- Cookies and local storage. Small identifiers used for sign-in, preferences, security, and first-party analytics. See our Cookie Policy.
- Approximate location. Derived from your IP address for security and to comply with regional rules. We do not collect precise GPS location for advertising.
2.3 Payment information
When you buy Coins or a membership, or when creators receive payouts, payments are processed by Stripe. Stripe handles your full card and bank details under its own terms; Helm does not see or store your full card number. We receive limited transaction records such as amount, date, status, and the last few digits of the payment method.
2.4 Information from third parties
- Platform links you add. If you add links to your pages on other services, we store only the URLs you enter to display them on your profile. We do not receive data from those services.
- Verification and safety sources. For Business and Brand verification, we may consult public business registries, and we may receive information from service providers that help us detect fraud and abuse.
3. How we use information
We use information to:
- provide and operate the Service, including your feed, messages, live streams, profile links, memberships, and monetization;
- process purchases of Coins and memberships and creator payouts through Stripe;
- keep accounts and the community safe by detecting fraud, spam, and abuse, enforcing our rules, and supporting parental controls;
- personalize your experience based on your account type and the interests and creators you choose, without third-party ad tracking;
- communicate with you about your account, safety, policy updates, and product news, with the ability to opt out of non-essential messages;
- measure and improve the Service through first-party analytics; and
- comply with law and enforce our agreements, including responding to lawful requests after review.
4. Legal bases for processing
Where the GDPR or similar laws apply, we rely on these legal bases:
- Contract. To provide the Service you signed up for.
- Legitimate interests. To keep Helm secure, prevent abuse, and improve the Service, balanced against your rights.
- Consent. Where required, for example certain cookies or optional communications; you can withdraw consent at any time.
- Legal obligation. To meet tax, financial, and other legal requirements.
5. No sale of data and no ad tracking
6. How we share information
We share information only as described here:
- Other users. Your public profile and public posts are visible to others. Content you restrict is shared only with the audience you choose.
- Service providers. Trusted vendors who help us run Helm, including Stripe for payments, Bunny for media storage and video delivery, and providers for hosting, email, and error monitoring. They receive only what they need and are contractually barred from using your data for their own purposes.
- Brand and creator matching. If you opt into creator or sponsorship features, brands you engage with can see the public profile information and analytics you choose to share.
- Legal and safety. When required by valid legal process or to protect rights, safety, and the integrity of the Service, after we review and, where appropriate, challenge the request. We notify you where permitted by law.
- Business transfers. If Helm is involved in a merger, acquisition, or sale of assets, information may transfer to the successor, which must honor this policy or notify you of changes.
7. How long we keep information
We keep your information while your account is active or as needed to provide the Service. After you delete your account, we delete or de-identify your personal information within 30 days, except where we must keep certain records longer to meet legal obligations (for example, financial and tax records, or preservation for a safety or law-enforcement matter). See our data deletion page for details.
8. How we protect information
We use administrative, technical, and physical safeguards designed to protect your information, including encrypted connections (HTTPS), encryption of sensitive data at rest, access controls on a least-privilege basis, and monitoring. No system is perfectly secure, but if we learn of a breach affecting your personal information, we will notify you and the appropriate authorities as required by law.
9. Children’s privacy (COPPA)
Helm is family-safe and takes children’s privacy seriously. Children under 13 may use Helm only through a Kid account linked to a verified Parent account, and only after we obtain verifiable parental consent as required by the Children’s Online Privacy Protection Act (COPPA).
- We collect only the information reasonably necessary for a child to use the Service.
- We do not serve behavioral or targeted advertising to minors, and we do not sell or share children’s personal information.
- Kid accounts have restricted messaging, kid-approved content, and family-only live streaming by default.
- A parent can review, correct, or delete their child’s information and revoke consent at any time from the Family area, which stops further collection and use.
If you believe a child under 13 has used Helm without parental consent, contact us at privacy@helmsocial.app and we will act promptly. Teen accounts (13 to 17) have additional protections and require parental confirmation.
10. Your rights and choices
No matter where you live, you can:
- Access and review your information in your account settings;
- Export a copy of your content and key data;
- Correct your profile and account information;
- Delete your account and personal information (see data deletion);
- Opt out of non-essential emails and adjust cookie and analytics choices; and
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
To make a request, use in-app settings or email privacy@helmsocial.app. We will verify your identity before acting and will not discriminate against you for exercising your rights.
11. California rights (CCPA / CPRA)
California residents have the rights to know, access, correct, and delete their personal information, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information, with a right to non-discrimination for exercising them. Helm does not sell or share personal information as those terms are defined under California law, and we do not use sensitive personal information to infer characteristics. To exercise your rights, email privacy@helmsocial.app with the subject line “California Privacy Request.” You may use an authorized agent.
12. Other United States state rights
Residents of states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Utah, Texas, and others) have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. Because Helm does not sell personal data or run targeted advertising, those opt-outs have nothing to apply to, but you may still exercise your access, correction, and deletion rights by emailing privacy@helmsocial.app. Where a state provides an appeal process, we will honor it.
13. European and United Kingdom rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights to access, rectify, erase, restrict, and object to processing, and the right to data portability. The legal bases on which we rely are described in Section 4. To exercise these rights, email privacy@helmsocial.app. You may also lodge a complaint with your local supervisory authority. You can reach our privacy team, which handles data protection matters, at the same address.
14. International data transfers
Helm is operated from the United States, and your information will be processed there. If you use Helm from outside the United States, you understand that United States privacy protections may differ from those in your country. Where required, we use appropriate safeguards for international transfers, such as the European Commission’s Standard Contractual Clauses.
15. Cookies and similar technologies
We use cookies and local storage for sign-in, security, preferences, and first-party analytics only. We do not use third-party advertising or cross-site tracking cookies. For the full list and how to control them, see our Cookie Policy. We honor the Global Privacy Control (GPC) signal as an opt-out request.
16. Shopify integration (Helm Store Sync)
Merchants can connect a Shopify store to Helm using our Shopify app, Helm Store Sync. This section explains the limited Shopify data the app processes and how we handle it. It applies in addition to the rest of this policy.
- What the app accesses. Product, inventory, and price data are read from and written to Shopify to keep the merchant’s catalog and stock in sync. This is not customer data. Order data is processed only to mirror a Helm order into the merchant’s Shopify admin so the merchant can fulfill it, and is limited to the shopper’s name, shipping address, and email.
- What the app does not do. The app does not access the merchant’s customer list or phone numbers, and it does not use this data for marketing, advertising, profiling, automated decision-making, resale, or AI model training.
- Roles. The merchant is the controller of its customers’ personal data. Helm acts as a processor on the merchant’s documented instructions, which are to sync the catalog and to create and fulfill orders. See our Data Processing Addendum.
- Minimization and purpose. We request only the Shopify permissions needed for the above, and we process only the three customer fields (name, address, email) required to create and fulfill an order.
- Retention and deletion. Order data is kept only for the order and fulfillment lifecycle and any legally required record-keeping, then removed. We support Shopify’s compliance webhooks: on a customer data request or redaction, or a shop uninstall or closure, we respond to or delete the corresponding data we hold.
- Security. Data is transmitted over TLS and stored in an access-controlled, encrypted-at-rest database. Access to this data is logged. The Shopify access token is stored server-side only and is never exposed to browsers or client code.
- No children’s data. This integration concerns a merchant’s commerce customers, not Helm’s under-13 users. No children’s data is processed through the Shopify sync.
Merchants and their customers can request access to or deletion of the data the app holds by emailing security@helmsocial.app, and Shopify’s built-in data-request and redaction tools are supported automatically.
17. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date and give notice, for example by email or a prominent in-app notice, before the change takes effect. Continued use of the Service after the effective date means you accept the updated policy.
18. Contact us
Helm Social, Inc.
Privacy: privacy@helmsocial.app
General: hello@helmsocial.app
For California, GDPR, or COPPA requests, please include a subject line that matches your request so we can route it quickly.